# lemlist: agent door 57, human door not measured
- Site: lemlist.com
- Scanned: 2026-09-08
- Scan type: Basic scan
- Business type: b2b_saas
- Report: https://www.seconddoor.io/r/lemlist-mr6fb5
- Scanner version: 15
Lemlist publishes prices and allows browser access, but API keys require a sales conversation and there is no machine-readable specification for integration.
## Scores
| Measure | Score |
| --- | --- |
| Humans | not measured |
| Agents | 57/100 (6/6 dimensions) |
| Composite | 57/100 |
Agent door only. The human door could not be measured on this scan. A Door Gap needs both doors, so this scan does not report one.
## What the machine actually did
The agent got through 8 of 14 requests, but could not read the site's own guide for language models. It came up empty on 5 other checks too.
- ok      reach the site at all
- ok      find out whether machines are welcome
- ok      ask whether the door opens for requests carrying the AI crawlers' names
- missing read the site's own guide for language models
- ok      find out what pages exist
- missing find a contact route for machines
- ok      find a published agent interface
- missing find an agent plugin manifest
- missing find out whether verified agents are recognised
- missing read the homepage as data rather than as a page
- missing find a machine readable API spec
- ok      read the developer documentation
- ok      read the prices without running JavaScript
- ok      find a comparison page worth citing
## Top issues
1. **No security.txt file is published, leaving no standard channel for security researchers to report vulnerabilities.** (machine_fetchable_trust)
2. **No OpenAPI specification is published, requiring developers to write API clients by hand from prose documentation.** (programmatic_onboarding)
3. **No llms.txt is published at the site root, so assistants get no curated map of what matters here.** (machine_discoverability)
The evidence and the recommended fix for each are on the report page: https://www.seconddoor.io/r/lemlist-mr6fb5
## Files generated from this scan
- **Pricing as Offer structured data** at `pricing page`, 20 minutes, developer. Verify: The next scan reads Offer structured data with a price and currency on the pricing page, and the pricing check credits it.
- **robots.txt rules for AI crawlers** at `/robots.txt`, 10 minutes, no developer needed. Verify: The next scan reads robots.txt and finds every search and agent crawler allowed, none of them kept off product or pricing paths.
- **Machine interfaces: where you stand** at `notes`, 10 minutes, no developer needed. Verify: The next scan finds the interface you published answering at its well-known path, and that check passes.
- **pricing.md** at `/pricing.md`, 20 minutes, no developer needed. Verify: The next scan fetches /pricing.md as text and records pricing as machine readable.
- **Organization structured data** at `homepage`, 15 minutes, developer. Verify: The next scan reads Organization and WebSite nodes in the homepage JSON-LD and the structured data check passes.
- **security.txt** at `/.well-known/security.txt`, 10 minutes, no developer needed. Verify: The next scan fetches /.well-known/security.txt as text and the security.txt check passes.
- **llms.txt** at `/llms.txt`, 15 minutes, no developer needed. Verify: The next scan fetches /llms.txt as text and the llms.txt check passes.
Each file is written from what this scan found on the site. The content is in the JSON once the evidence is opened: https://www.seconddoor.io/api/reports/lemlist-mr6fb5
## The agent door
- **machine_discoverability** 98/100. No AI crawler is blocked by robots.txt or user agent rules. The site serves a real browser normally, publishes a sitemap with 1153 URLs, and renders key pages without JavaScript. Comparison pages are listed and readable.
- **programmatic_onboarding** 24/100. Authentication is documented in prose at developer.lemlist.com, and endpoint examples are shown. No OpenAPI spec exists at any standard path, no code samples are provided, and API key issuance is not self-serve.
- **pricing_legibility** 85/100. 10 prices are readable without JavaScript on the pricing page, stated in USD per seat. No tier is gated behind a sales contact. The Enterprise plan is named but not priced, which is standard practice for custom deals and does not obscure.
- **agent_aware_instrumentation** 58/100. An MCP manifest is published at https://developer.lemlist.com/.well-known/mcp.json, enabling Claude and other MCP-aware agents to discover and call the API.
- **machine_fetchable_trust** 40/100. No security.txt file is published at /.well-known/security.txt. The homepage responds to automated requests with HTTP 200 and serves content normally. No Web Bot Auth signals are present.
- **commercial_rails** 35/100. Prices are published in raw HTML.
## The human door
- **steps_to_first_value** not measured. Could not verify: this scan did not reach the pages that would show it.
- **required_fields** not measured. Could not verify: this scan did not reach the pages that would show it.
- **verification_walls** not measured. Could not verify: this scan did not reach the pages that would show it.
- **error_recovery** not measured. Could not verify: this scan did not reach the pages that would show it.
---
Scored by SecondDoor. Method: https://www.seconddoor.io/methodology
Scan another site: https://www.seconddoor.io
Rate an issue or this report: POST https://www.seconddoor.io/api/feedback, or the rate_fix tool on https://www.seconddoor.io/api/mcp
